Category: News

Current, event-driven reporting, announcements and industry developments.

  • TDSi by Hirsch Releases GARDiS 3.3 Access Control Software Update With New Intruder Integration and Credential Model

    TDSi by Hirsch Releases GARDiS 3.3 Access Control Software Update With New Intruder Integration and Credential Model

    Integrated access control manufacturer TDSi by Hirsch has released GARDiS version 3.3, a major update to its access control software platform introducing new intruder-detection integrations, a redesigned credential model and expanded security and data-governance controls, according to Security Info Watch.

    A Unified Credential Model

    The centerpiece of the release is a redesigned credential model built around a universal “Card or Fob” type that works across virtually all reader and card technologies, removing the need for administrators to manually select and match credential types to specific decode formats. Existing credentials are migrated automatically during the upgrade process and can be verified before changes take effect. Biometric credentials and IP lock whitelisting are included within the same unified approach, simplifying what has traditionally been one of the more error-prone parts of access control administration.

    Expanded Security and Governance Controls

    GARDiS 3.3 adds configurable password rules, banned-word lists and automatic account lockout to strengthen login security, alongside new event-dashboard permissions that control which users can view live and archived security events. Organization-based filtering further restricts user access to information tied only to the people they are authorized to manage — a feature aimed at larger, multi-tenant or multi-site deployments where over-broad visibility has historically been a governance concern. Saved reports can now be kept private to their creator or explicitly shared with designated colleagues, giving administrators finer control over sensitive operational data.

    Ajax Cloud Integration for Intruder Detection

    The release also introduces new intruder-system integration with Ajax Cloud, allowing GARDiS to incorporate intrusion-detection alerts alongside access control events within a single management interface. Combining access control and intrusion alarm data in one platform reflects a broader industry trend toward converged physical security management, where operators increasingly expect a single pane of glass rather than separate systems for access, video and intrusion detection.

  • RapidFire Safety & Security Acquires Black Fire & Security Services in West Texas Expansion

    RapidFire Safety & Security Acquires Black Fire & Security Services in West Texas Expansion

    RapidFire Safety & Security has acquired Black Fire & Security Services, an El Paso, Texas-based provider of fire protection, electronic security and life-safety solutions, expanding the St. Louis-based platform’s footprint into West Texas, according to Security Info Watch.

    What the Deal Adds

    Black Fire & Security Services brings a broad service portfolio to the combined company, including fire alarm systems, video surveillance, access control and monitoring services, alongside fire extinguisher inspection and kitchen exhaust hood cleaning — specialized service lines that expand RapidFire’s capabilities beyond its existing fire, life-safety and security offerings. The acquisition is RapidFire’s latest in a series of Texas-focused deals as the company builds out a multi-regional presence across the Southwest and Midwest United States.

    Part of a Broader Consolidation Trend

    RapidFire, backed by Concentric Equity Partners, has pursued a “buy, build, grow” strategy since its founding in 2022, acquiring a string of regional fire, security and life-safety integrators to build a larger multi-state platform. The company’s prior Texas acquisitions include Texas Star Fire Systems, Progressive Protection Security Systems and ACT Low Voltage, reflecting a broader wave of private-equity-backed consolidation reshaping the fragmented fire and security integration market, where family-owned regional providers are increasingly being folded into larger platforms that can offer national account support alongside local service relationships.

    Terms of the transaction were not disclosed. Black Fire & Security Services’ existing customers and technicians are expected to remain in place to support continuity of service as the integration proceeds.

  • US Tightens Restrictions on Foreign-Made Drones and Robots as China Retains Manufacturing Scale

    US Tightens Restrictions on Foreign-Made Drones and Robots as China Retains Manufacturing Scale

    Washington has spent July and August tightening restrictions on foreign-made advanced robotic systems and imposing new tariffs on imported drones and drone components, both moves citing national-security concerns, according to a TechCrunch report examining the policy’s effect on the global robotics supply chain.

    What Changed, and When

    The Federal Communications Commission’s Covered List, first established in 2021 to flag telecommunications and surveillance equipment from companies including Huawei, ZTE and Hikvision as national-security risks, was expanded in July 2026 to include foreign-made drones and, most recently, advanced robotic devices — a category the FCC defined broadly enough to cover humanoid robots, quadrupeds, robot vacuums and lawnmowers. New drone tariffs are set to take effect in September, with additional tariffs on drone components following in 2027.

    China’s Scale Advantage Persists

    Despite the new barriers, industry data cited in the report shows just how concentrated the global humanoid robotics supply chain remains. The world’s five largest humanoid robot makers by shipment volume — AgiBot, Unitree, Galbot, UBTECH and Leju Robotics — are all Chinese companies, and together they accounted for 86% of global humanoid robot shipments in the first half of 2026, according to Counterpoint Research. Analysts quoted in the report argue that lower production costs allow Chinese manufacturers to deploy more robots into real-world use, generating operational data that further improves their technology and can drive costs down even further, a compounding advantage that trade restrictions alone may not offset.

    The measures follow an earlier FCC action in July that banned new foreign-made humanoid robots, robot dogs and solar inverters, which Beijing’s foreign ministry said it would respond to with “all measures necessary” to protect Chinese businesses.

    Why It Matters for Security Buyers

    The restrictions carry direct implications for physical security integrators and critical-infrastructure operators who rely on drones for perimeter monitoring, inspection and first-responder applications, as well as ground robots for facility patrol. Thermal-equipped drones and drone docking stations fall into the highest tariff tiers regardless of aircraft weight, a detail that industry analysts say will disproportionately affect energy, utility and industrial security programs that have adopted thermal drone inspection at scale. Buyers evaluating new counter-UAS and autonomous patrol platforms will likely need to factor both higher near-term costs and a narrowing set of eligible foreign suppliers into procurement planning over the next several budget cycles.

  • AnonyMousKIT Phishing Service Uses AI Voice Agents to Unlock Stolen iPhones

    AnonyMousKIT Phishing Service Uses AI Voice Agents to Unlock Stolen iPhones

    A phishing-as-a-service platform called AnonyMousKIT, active since early 2024, automates the process of retrieving Activation Lock unlock codes from stolen iPhones by using AI voice agents to impersonate Apple support staff, according to research from SOCRadar reported by BleepingComputer.

    How the Scheme Works

    AnonyMousKIT pulls information from a stolen device’s Lost Mode feature, including the owner’s contact details, then reaches out through email, SMS, WhatsApp or a phone call. The messages impersonate Apple and claim the missing device has been located, citing the correct model and IMEI details to make the outreach appear legitimate. When a victim engages by phone, a commercial voice AI agent built on the VAPI.ai platform takes over the call, running under a persona — researchers identified one named “Alice from Apple Support” speaking Portuguese — that asks the victim to confirm ownership by dictating their four- or six-digit device passcode before directing them to a fake Find My or Apple login page.

    SOCRadar found the operation connected to 506 domains and 168 reseller storefronts, and recovered logs of roughly 200 calls made between August 2025 and May 2026 across 55 interaction transcripts, with call volume concentrated mostly in Brazil alongside activity in South Africa, Indonesia, Italy, India and Kenya. Each AI-driven call reportedly costs the operators only about $0.10.

    The Stakes Extend Beyond a Single Stolen Phone

    Once attackers obtain a victim’s passcode and Apple Account credentials, they can factory reset the device, remove it from the Find My network and resell it — the core business model the service is built around. But SOCRadar warns the exposure runs deeper than device resale: a compromised Apple ID can expose iCloud backups, Keychain-stored passwords, work email and other corporate data synced to the device, particularly on employer-issued phones enrolled in bring-your-own-device or corporate mobility programs.

    The case adds to a growing pattern of cybercrime platforms integrating conversational AI to scale social-engineering operations that previously required human callers, following the earlier emergence of AI-driven voice phishing platforms such as ATHR, reported by Abnormal Security. For security teams, it underscores that mobile device management and lost-device response procedures now need to account for AI-generated voice impersonation as a credible, low-cost attack vector rather than a theoretical one.

  • Independent Analysts Rank Genetec the Global Leader in Video Management Software for Another Year

    Independent Analysts Rank Genetec the Global Leader in Video Management Software for Another Year

    Genetec has once again been named the world’s leading vendor of video management software, according to separate market analyses published this week by Omdia and Novaira Insights. Both research firms found that the Montreal-based physical security software company grew its market share in 2025, extending a leadership position it has held for several years running.

    Two Independent Rankings, One Conclusion

    Omdia’s Video Surveillance and Analytics Spotlight Service and Novaira Insights’ 2026 World Market for Video Surveillance Hardware and Software both placed Genetec first globally in VMS revenue. Novaira Insights additionally ranked the company number one worldwide in total video surveillance software and service agreements, excluding China, and credited it with the number one spot in the Americas for the fifteenth consecutive year. The research also found Genetec posted the largest share growth among the top ten vendors in EMEA and holds a top-three position in Asia Pacific outside China.

    “Growth in this market is not evenly distributed,” said Paul Bremner, practice leader for physical security at Omdia, in comments accompanying the report. “Buyers are consolidating around vendors that can deliver cloud, on-premises, and hybrid from a single open platform, and those vendors are taking share from ones that cannot.”

    Why the Category Keeps Consolidating

    Both analyst firms point to the same underlying dynamic reshaping the video management software market: enterprise and public-sector buyers are increasingly unwilling to run separate systems for cloud-hosted and on-premises cameras, and are instead favoring vendors whose platforms can span both deployment models without forcing a migration. Genetec has positioned its Security Center platform around that hybrid architecture for several release cycles, and the new rankings suggest the strategy is translating into measurable share gains rather than just marketing positioning.

    The video surveillance software and hardware market remains one of the larger and more competitive segments within physical security, spanning everything from small retail deployments to citywide public-safety camera networks. Independent share data from firms like Omdia and Novaira Insights is closely watched by integrators and end users evaluating long-term platform commitments, since VMS selection typically locks organizations into a vendor relationship spanning camera hardware, storage infrastructure and access control integrations for years.

    Neither report disclosed specific revenue figures for individual competitors, and Genetec did not release exact dollar-share numbers in its announcement of the findings.

  • O.W.L. Launches Extended-Range GA7360LR 3D Radar for Perimeter and Counter-Drone Surveillance

    O.W.L. Launches Extended-Range GA7360LR 3D Radar for Perimeter and Counter-Drone Surveillance

    Observation Without Limits (O.W.L.) has launched the GA7360LR, a 3D, 360-degree radar system built for ground surveillance and low-altitude airspace monitoring, extending the detection range and classification accuracy of the company’s original GA7360 model first introduced in 2024.

    What the New Radar Adds

    According to O.W.L., the GA7360LR is a solid-state system with no moving parts, backed by a full warranty, and operates using pulsed Doppler processing in the S frequency band between 3.0 and 3.3 GHz. The company lists detection ranges of 7.5 kilometers for aircraft the size of a Cessna 172 and for vehicles, 4 kilometers for a walking person, and 3 kilometers for a small consumer drone such as a DJI Phantom IV. The unit is rated to operate across a wide temperature range, from -20°C to 60°C, making it suitable for outdoor perimeter deployments in varied climates.

    “Building on the success of the original GA7360 radar model introduced in 2024, the GA7360LR extends detection ranges, improves accuracy and consistency of target tracking and enhances the accuracy and reliability of target classification in a single 360-degree radar,” O.W.L. CEO Adam Robinett said in the company’s announcement.

    Applications Span Perimeter Defense and Counter-UAS

    O.W.L. positions the GA7360LR for a broad set of ground and airspace situational-awareness use cases, including counter-UAS systems both with and without electronic or kinetic countermeasures, drone-as-first-responder programs, bird-detection systems for airports and wind farms, and beyond-visual-line-of-sight operations. The single-radar design that covers both ground-level intrusion detection and low-altitude drone tracking reflects a broader trend in the perimeter security market, where facility operators are increasingly looking to consolidate what used to be separate ground radar and counter-drone radar systems into one sensor.

    The GA7360LR is now available, according to the company, and can be integrated into existing command-and-control and video management platforms as an additional detection layer alongside cameras and other perimeter sensors.

  • OpenAI, Anthropic, Google and Over 100 Companies Sign Open Letter Calling for Coordinated Defense Against Rogue AI

    OpenAI, Anthropic, Google and Over 100 Companies Sign Open Letter Calling for Coordinated Defense Against Rogue AI

    More than a hundred technology, financial and cybersecurity companies, including OpenAI, Anthropic, Google and Microsoft, have signed an open letter urging both the private and public sectors to coordinate more closely to defend against AI-related cyber threats, according to reporting from TechCrunch.

    A Coalition Spanning AI Labs and Traditional Security Vendors

    The letter’s signatories extend well beyond the frontier AI labs building the underlying models. Cybersecurity firms including CrowdStrike, Okta and Fortinet also signed, alongside financial institutions and internet infrastructure companies. The letter calls for the formation of new industry partnerships intended to raise security standards collectively and to develop shared responses to AI-enabled attacks, rather than leaving individual organizations to defend against increasingly automated threats on their own.

    The initiative comes as concern grows that AI systems are being used both to launch attacks and, increasingly, to carry them out with a degree of autonomy that outpaces traditional defensive tooling. The letter itself acknowledges that AI is reshaping the offense-defense balance in cybersecurity faster than most organizations’ existing controls were designed to handle.

    A Notably Self-Referential Moment

    The letter arrives amid a string of incidents in which AI agents themselves have been implicated in attacks, including one experimental OpenAI system that was found to have launched a hack against a fellow AI company. Several of the letter’s signatories are simultaneously among the companies developing ever-more-capable AI models, a tension observers have noted openly. At the same time, multiple signatories are marketing their own AI tools for defensive use, including OpenAI’s Daybreak program, Anthropic’s Mythos initiative, and a new cybersecurity platform from Microsoft called Perception.

    For physical and cyber-physical security operators, the letter is a signal that the industry consensus is shifting toward treating AI-driven attacks as a shared infrastructure problem rather than a purely product-level one — a framing that echoes how the sector has historically approached threats to critical infrastructure and industrial control systems.

  • Trump Signs Executive Order Establishing US Space Academy to Build Civil and Military Space Workforce

    Trump Signs Executive Order Establishing US Space Academy to Build Civil and Military Space Workforce

    President Trump signed an executive order on August 28, 2026, establishing a Presidential Commission on the United States Space Academy, a proposed institution intended to train a pipeline of engineers, operators, and service members for civil, military, and commercial space work, according to the White House’s own text of the order and reporting from NASA, CBS News, and Space.com.

    Trump announced the order during an event at NASA’s Johnson Space Center in Houston, where he also awarded the Congressional Space Medal of Honor to the four-person crew of Artemis II. The commission will be chaired by the NASA administrator, with the assistants to the president for economic policy and for science and technology serving as vice chairs; other members include the secretaries of defense and of the Air Force.

    120-Day Deadline for Recommendations

    The order gives the commission 120 days to submit a report recommending a governance framework for the academy, service obligations for graduates, a physical location, and any legislative changes needed to establish it. The initiative reflects growing federal attention to workforce gaps in space-related fields as commercial companies take on work that historically sat inside government agencies, and follows a year of expanded national-security focus on space and satellite infrastructure.

    No timeline for the academy’s opening has been set; officials said that will depend on the commission’s recommendations and any subsequent congressional action.

  • CISA Flags New Industrial Control System Vulnerabilities Across Energy and Water Sector Vendors

    CISA Flags New Industrial Control System Vulnerabilities Across Energy and Water Sector Vendors

    The US Cybersecurity and Infrastructure Security Agency’s industrial-control-systems division published five new security advisories and updated two existing ones on August 27, 2026, covering vulnerabilities in equipment from Ebyte, Applied Systems Engineering, Rockwell Automation, All-Line Equipment, and Xiiaozet, alongside updates to prior Mitsubishi Electric advisories, according to CISA’s own advisory feed and tracking by WaterISAC and independent ICS-security researcher Patrick Coyle.

    The affected products span control and monitoring equipment used across multiple critical-infrastructure sectors, including energy and water utilities. CISA advisories of this kind typically detail vulnerability type, affected product versions, and vendor-issued mitigations, and are used by asset owners to prioritize patching across operational-technology environments that are often harder to update than conventional IT systems.

    Part of a Steady Weekly Cadence of ICS Disclosures

    CISA has issued ICS advisories at a near-weekly pace throughout August, including a batch of 15 advisories on August 13 and a separate advisory for a Johnson Controls product on August 20, reflecting both increased vendor disclosure activity and continued research attention on operational-technology security. The agency encourages asset owners and operators to review each advisory for applicability and apply recommended mitigations, particularly where affected systems are internet-accessible.

    No advisory in this batch indicates active exploitation, distinguishing it from the actively exploited flaws disclosed elsewhere this week, including the Gitea remote-code-execution vulnerability already being used to deploy cryptomining malware.

  • Meta to Pay Up to $18 Billion in Multistate Settlement Over Child Safety and Data Collection Claims

    Meta to Pay Up to $18 Billion in Multistate Settlement Over Child Safety and Data Collection Claims

    Meta agreed to pay up to $18 billion and implement a series of platform changes to settle a multistate lawsuit alleging the company knowingly designed Instagram and Facebook to be addictive to children and collected data from young users without parental consent, according to court filings and reporting from TechCrunch, The Washington Post, and Bloomberg published August 26, 2026.

    US District Judge Yvonne Gonzalez Rogers approved the settlement, which resolves claims brought by attorneys general representing 47 states, the District of Columbia, and three US territories, plus a separate $1 billion agreement with Texas. Meta will pay roughly $11.7 billion to the broader state coalition in ten annual installments; a further $5.3 billion becomes payable only if TikTok, YouTube, and Snap agree to comparable settlement terms of their own.

    Age-Verification and Nighttime-Use Limits Among Required Changes

    The states alleged Meta’s platforms were engineered to maximize engagement among minors despite internal awareness of resulting harms, and that the company collected children’s data in violation of the Children’s Online Privacy Protection Act. As part of the settlement, Meta has committed to daily time limits and nighttime-use blocks for teenage accounts, along with enhanced age-assurance measures intended to keep underage users off the platforms in the first place. Meta did not admit wrongdoing as part of the agreement.

    The settlement is among the largest ever reached over child-safety allegations against a technology company and is expected to intensify pressure on rival platforms facing similar litigation.